SepAdjustPrivileges
INT64 __fastcall SepAdjustPrivileges(
_TOKEN *Token,
INT64 MakeChanges,
UINT8 DisableAllPrivileges,
UINT64 PrivilegeCount,
_LUID_AND_ATTRIBUTES *NewState,
_TOKEN_PRIVILEGES *PreviousState,
UINT *ReturnLength,
UINT *ChangeCount,
UINT8 *ChangesMade){
unsigned int v10;
unsigned int v11;
void *v13;
INT64 v14;
__int64 v16;
unsigned __int64 Present;
__int64 v18;
_LUID Luid;
unsigned __int64 v20;
unsigned int Attributes;
int v22;
unsigned int v23;
char v24;
int v25;
UINT v26;
_LUID v27;
__int64 v28;
bool v29;
__int64 v30;
unsigned __int64 v31;
_LUID v32;
__int64 v33;
__int64 v34;
unsigned int v35;
__int64 v36;
int v37;
__int64 v38;
unsigned __int64 v39;
__int64 v40;
signed int v41;
unsigned __int64 Enabled;
BOOL v43;
unsigned int v44;
__int64 v45;
__int64 v46;
__int64 v47;
UINT64 EnabledCount;
INT64 AccessGranted;
char v50;
UINT8 pbDominate;
UINT8 v52[2];
int v53;
unsigned int DisabledCount;
int DisabledCount_4;
int v56;
__int64 v57;
_LUID v58;
UINT8 *v59;
UINT *v60;
void *Buf1[2];
_LUID_AND_ATTRIBUTES result[36];
_LUID_AND_ATTRIBUTES v63[36];
v10 = 0;
v11 = 0;
v60 = ReturnLength;
v53 = 0;
DisabledCount = 0;
v50 = MakeChanges;
v58 = 0i64;
pbDominate = 0;
v52[0] = 0;
LOBYTE(v56) = 0;
LODWORD(v57) = PrivilegeCount;
v59 = ChangesMade;
*(_OWORD *)Buf1 = 0i64;
memset((INT64)result, 0i64);
memset((INT64)v63, 0i64);
*ChangeCount = 0;
*ChangesMade = 0;
SepCopyTokenIntegrity((INT64)Token);
v13 = Buf1[0];
LODWORD(v14) = RtlSidDominates(Buf1[0], SeHighMandatorySid, &pbDominate);
DisabledCount_4 = v14;
if( (int)v14 < 0 )
return v14;
if( !pbDominate )
{
LODWORD(v14) = RtlSidDominates(v13, *(PVOID *)&SeMediumMandatorySid, v52);
DisabledCount_4 = v14;
if( (int)v14 < 0 )
return v14;
v37 = (unsigned __int8)v56;
if( !v52[0] )
v37 = 1;
v56 = v37;
}
if( DisableAllPrivileges )
{
v24 = v50;
v41 = 0;
v23 = 0;
do
{
Enabled = Token->Privileges.Enabled;
if( (Enabled & (1i64 << v41)) != 0 )
{
if( v24 )
{
v43 = ((1i64 << v41) & Token->Privileges.EnabledByDefault) != 0;
v57 = v41;
v44 = v43 + 2;
v58 = (_LUID)v41;
v45 = v23++;
v46 = v45;
result[v46].Luid = (_LUID)v41;
result[v46].Attributes = v44;
if( PreviousState )
{
v47 = *ChangeCount;
PreviousState->Privileges[v47].Luid = (_LUID)v41;
PreviousState->Privileges[v47].Attributes = v44;
Enabled = Token->Privileges.Enabled;
}
_bittestandreset64((__int64 *)&Enabled, (unsigned int)v41);
v24 = v50;
Token->Privileges.Enabled = Enabled;
}
++*ChangeCount;
}
++v41;
}
while( (unsigned int)v41 <= 0x24 );
LABEL_15:
v25 = DisabledCount_4;
goto LABEL_16;
}
if( !(_DWORD)v57 )
{
v23 = 0;
LABEL_14:
v24 = v50;
goto LABEL_15;
}
v16 = (unsigned int)v57;
do
{
Present = Token->Privileges.Present;
v18 = 1i64 << NewState->Luid.LowPart;
if( (Present & v18) == 0 )
goto LABEL_10;
Luid = NewState->Luid;
++v10;
v58 = NewState->Luid;
v20 = Token->Privileges.Enabled;
Attributes = NewState->Attributes;
v22 = (((1i64 << SLOBYTE(v58.LowPart)) & v20) != 0 ? 2 : 0) | (((1i64 << SLOBYTE(v58.LowPart)) & Token->Privileges.EnabledByDefault) != 0);
if( (Attributes & 4) != 0 )
{
if( v50 )
{
Token->Privileges.Enabled = v20 & ~(1i64 << SLOBYTE(Luid.LowPart));
Token->TokenFlags |= 0x800u;
Token->Privileges.Present = Present & ~(1i64 << SLOBYTE(Luid.LowPart));
}
}
else if( (Attributes & 2) != 0 )
{
if( (v20 & v18) != 0 )
goto LABEL_10;
if( !v50 )
goto LABEL_30;
v27 = v58;
if( PreviousState )
{
v36 = *ChangeCount;
PreviousState->Privileges[v36].Luid = v58;
PreviousState->Privileges[v36].Attributes = v22;
}
v28 = v11++;
v29 = pbDominate == 0;
v30 = v28;
v63[v30].Luid = v27;
v63[v30].Attributes = v22;
if( !v29 )
goto LABEL_29;
if( v52[0] )
{
v38 = 0x1120160684i64;
if( _bittest64(&v38, NewState->Luid.LowPart) )
goto LABEL_52;
}
else
{
if( !(_BYTE)v56 )
goto LABEL_30;
v40 = 1i64 << NewState->Luid.LowPart;
if( (Token->TokenFlags & 0x4000) != 0 )
{
if( (v40 & 0x200800000i64) != 0 )
{
LABEL_29:
v31 = Token->Privileges.Enabled;
_bittestandset64((__int64 *)&v31, Luid.LowPart);
Token->Privileges.Enabled = v31;
}
else
{
LABEL_52:
++v53;
}
LABEL_30:
++*ChangeCount;
goto LABEL_10;
}
if( (v40 & 0x202800000i64) == 0 )
goto LABEL_52;
}
v39 = Token->Privileges.Enabled;
_bittestandset64((__int64 *)&v39, Luid.LowPart);
Token->Privileges.Enabled = v39;
++*ChangeCount;
}
else if( (v20 & v18) != 0 )
{
if( v50 )
{
v32 = v58;
if( PreviousState )
{
v33 = *ChangeCount;
PreviousState->Privileges[v33].Luid = v58;
PreviousState->Privileges[v33].Attributes = v22;
v20 = Token->Privileges.Enabled;
}
v34 = DisabledCount;
v35 = DisabledCount + 1;
_bittestandreset64((__int64 *)&v20, Luid.LowPart);
result[v34].Luid = v32;
Token->Privileges.Enabled = v20;
result[v34].Attributes = v22;
DisabledCount = v35;
}
++*ChangeCount;
}
LABEL_10:
++NewState;
--v16;
}
while( v16 );
if( v10 >= (unsigned int)v57 && !v53 )
{
v23 = DisabledCount;
goto LABEL_14;
}
v24 = v50;
v25 = 262;
v23 = DisabledCount;
LABEL_16:
if( *ChangeCount && v24 )
{
*v59 = 1;
LOBYTE(AccessGranted) = v25 >= 0;
LODWORD(EnabledCount) = v11;
SepAdtTokenRightAdjusted(Token, result, v23, v63, EnabledCount, AccessGranted);
}
if( PreviousState )
{
if( *ChangeCount > 1 )
v26 = 12 * *ChangeCount + 4;
else
v26 = 16;
*v60 = v26;
}
return(unsigned int)v25;
}Referenced by:
NtAdjustPrivilegesToken